Congress of tfjc Unites States 

®2Ua£rt)mo;toii, BC 20510 

October 31,2019 

The Honorable William P. Barr, Attorney General 

Department of Justice 

950 Pennsylvania Avenue, N.W. 

Washington, D.C. 20530 

Dear Attorney General Barr, 

Child sexual abuse imagery (CSA1) is a plague that companies, government and civil society 
groups must work together to purge from our society. However, we have serious concerns 
about the Department of Justice’s (DOJ) misguided, hypocritical efforts to pressure 
technology companies like Facebook into subverting the encryption that protects their 
messaging apps to enable government access. This proposal will not meaningfully address 
the problem of CSAI, because illegal content will simply move to the dark web and to 
foreign commercial providers that are beyond the reach of U.S. law enforcement, while 
exposing millions of law-abiding Americans to new cybersecurity threats from stalkers, 
hackers and other criminals. 

CSAI is a heinous problem, but it is one that American technology companies have been 
working to address. As the New York Times described in a recent story, the major tech 
platforms have taken significant voluntary steps to detect and flag CSAI. 1 Last year, tech 
companies sent 45 million tips to law enforcement. This shocking number highlights not only 
the enormous nature of the CSAI problem, but also the inadequacy of the government’s 
efforts to date. Quite simply, law enforcement agencies are receiving orders of magnitude 
more tips than they have the resources to investigate. That must change. 

As Members of Congress, we take our responsibility to protect our nation’s children 
seriously. This is why Congress passed the PROTECT Act of 2008 and the Child Protection 
Act of 2012, both of which require DOJ to take steps to coordinate a cross-sectoral approach 
to reducing CSAI. Unfortunately, DOJ has failed to comply with parts of these laws, 
including a requirement that it submit to Congress a National Strategy for Child Exploitation 
Prevention and Interdiction every two years. 2 Further, experts have highlighted several 
immediate steps law enforcement agencies can take to increase their ability to use digital 
evidence, beyond stopping encryption. 3 

Rather than focusing the government’s resources on reducing the backlog of CSAI reports 
from tech companies or implementing the reforms required by law and recommended by 
experts, you have launched a misguided public campaign to pressure Facebook to abandon a 
cybersecurity upgrade. Facebook announced in January that it intends to upgrade its 
Instagram and Messenger services with the same form of default encryption that its 
WhatsApp service has used since 2016. This encryption technology, known as the Signal 
Protocol, was developed in 2014 by U.S. government-funded researchers, who first included 
it in Signal, a U.S. government funded app that is popular with cybersecurity experts, policy 
makers, journalists, and human rights organizations. 
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Every day, government officials in the White House, DOJ, and Congress use end-to-end 
encrypted messaging apps like Signal and WhatsApp to protect their unclassified 
communications. The popularity of these apps among policy makers is not surprising. The 
Department of Homeland Security revealed last summer that it discovered cell phone spying 
devices near the White House and other sensitive locations in Washington, D.C. 4 Likewise, 
in Senate testimony last year, William Evanina, the top counter-intelligence official in the 
Office of the Director of National Intelligence, recommended that government officials 
encrypt their unclassified telephone conversations. 5 

If senior government officials in Washington, D.C. have opted to secure their 
communications with end-to-end encryption, why should the conversations of millions of 
law-abiding Americans using Instagram and Facebook Messenger not also be protected from 
hackers? 


The DOJ’s public relations campaign to prevent Americans from having the same level of 
cybersecurity protections as government officials is not just hypocritical, but it has been 
repeatedly criticized by cryptographers and other leading cybersecurity experts. These 
technical experts have made it clear that weakening encryption to enable law enforcement 
access will unnecessarily expose Americans’ communications to hacking by criminals and 
foreign spies. Moreover, if Facebook does bow to your pressure campaign, CSAI predators 
will simply move to foreign platforms that refuse to cooperate with U.S. law enforcement 
and are outside of the jurisdiction of our laws and courts. Shifting the problem of CSAI to 
platforms operated by foreign companies or operating on the dark web would only damage 
our government’s ability to respond to the CSAI epidemic. 6 

Aside from cybersecurity experts, 7 the list of people who oppose backdoors includes many 
former intelligence and military leaders, including Mike McConnell, former Director of the 
National Security Agency and former Director of National Intelligence; Michael Chertoff, 
former Homeland Security Secretary; James Baker, former General Counsel of the Federal 
Bureau of Investigation, William Lynn, former Deputy Defense Secretary; and Michael 
Hayden, former Director of the National Security Agency and former Director of the Central 
Intelligence Agency. 8 


We share your concern about CSAI and commit to providing the DOJ with the resources 
necessary to investigate and prosecute the criminals who create, distribute, and download this 
material. However, we urge you to stop demanding that private companies purposefully 
weaken their encryption for the false pretense of protecting children. 


Most gratefully, 



ember of Congress 
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Ron Wyden 
U.S. Senator 
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